← 返回时间线

paper

Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions

arXiv ↗
ID
2609.06140
分类
首次捕获
2026-09-10
状态
unread
作者
Gregory N Frank
信号
🔥 3

信号历史

  • 2026-09-10HF Daily Papers · 🔥3
暂无信号数据

摘要

Agents can turn shared infrastructure into a channel for coordinated intrusion. The Hugging Face incident and a separate public-wiki investigation show why a security assessment may need evidence from several executions and the artifacts they leave behind. We argue that the operational unit of defence should be a revisable coordination episode linking observed transfers, task authority, and response history. The central research problem is prospective episode discovery: finding which actions belong together before an evaluator supplies their membership. We define unsanctioned coordination relative to collaboration and delegated-authority policy, connect storage-mediated coordination to stigmergy, and specify the evidence needed to distinguish influence from common causes. First-contact signals are one possible input to discovery; the design also follows inherited state and later use. A proposed evaluation compares isolated actions, rolling windows, known groups, and prospectively discovered episodes at matched review cost and false-alert workload. It measures harmful outcomes across all assigned population runs and tests recurrence after channel closure and state quarantine. A checksum-verified reconstruction of the public wiki export separates the decline in retained writes from later administrative cleanup. The contribution is an incident-grounded position, descriptive analysis, and evaluation design. It makes the recommendation to monitor across executions testable without claiming a new detector or a measured containment benefit.

我的笔记

还没有笔记。

在 GitHub 上写笔记 ↗(新建 content/notes/2609.06140.md,PR 合并后本页自动更新)